- Mastering OpenStack(Second Edition)
- Omar Khedher Chandan Dutta Chowdhury
- 206字
- 2021-07-02 23:52:37
Keystone - identity management
From an architectural perspective, Keystone presents the simplest service in the OpenStack composition. It is the core component and provides an identity service comprising authentication and authorization of tenants in OpenStack. Communications between different OpenStack services are authorized by Keystone to ensure that the right user or service is able to utilize the requested OpenStack service. Keystone integrates with numerous authentication mechanisms such as username/password and token/authentication-based systems. Additionally, it is possible to integrate it with an existing backend such as the Lightweight Directory Access Protocol (LDAP) and the Pluggable Authentication Module (PAM).
Keystone also provides a service catalog as a registry of all the OpenStack services.
With the evolution of Keystone, many features have been implemented within recent OpenStack releases leveraging a centralized and federated identity solution. This will allow users to use their credentials in an existing, centralized, sign-on backend and decouples the authentication mechanism from Keystone.
The federation identity solution becomes more stable within the OpenStack Juno release, which engages Keystone as a Service Provider (SP), and uses and consumes from a trusted Provider of Identity (IdP), user identity information in SAML assertions, or OpenID Connect claims. An IdP can be backed by LDAP, Active Directory, or SQL.
- Dreamweaver CS3+Flash CS3+Fireworks CS3創(chuàng)意網站構建實例詳解
- 腦動力:C語言函數速查效率手冊
- 手把手教你玩轉RPA:基于UiPath和Blue Prism
- 并行數據挖掘及性能優(yōu)化:關聯規(guī)則與數據相關性分析
- 計算機網絡技術基礎
- 樂高機器人—槍械武器庫
- Prometheus監(jiān)控實戰(zhàn)
- 步步圖解自動化綜合技能
- 西門子變頻器技術入門及實踐
- 多媒體制作與應用
- INSTANT Adobe Story Starter
- AVR單片機工程師是怎樣煉成的
- Practical AWS Networking
- Kubernetes on AWS
- Practical Network Automation